Update weekly update - #8662
Merged
Merged
Conversation
Pull request dashboard statusWaiting on reviewers · refreshed 2026-07-28 14:27 UTC Review the latest changes. Status above doesn't look right?
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8662 +/- ##
=========================================
Coverage 91.46% 91.46%
Complexity 10456 10456
=========================================
Files 1021 1021
Lines 27647 27647
Branches 3242 3242
=========================================
Hits 25288 25288
Misses 1616 1616
Partials 743 743 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
renovate
Bot
force-pushed
the
renovate/weekly-update
branch
from
July 28, 2026 09:06
4886d33 to
88adb24
Compare
jkwatson
approved these changes
Jul 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v7.0.0→v7.0.1v5.5.0→v5.6.0v4.4.0→v4.5.2v4.37.0→v4.37.3v4.2.0→v4.2.3v0.2.1→v0.4.0v2.4.3→v2.4.4d3400aa→cea0e60d158a97→5f1cdbcb7f4819→3131b4cRelease Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
actions/setup-java (actions/setup-java)
v5.6.0Compare Source
What's Changed
Full Changelog: actions/setup-java@v5...v5.6.0
docker/login-action (docker/login-action)
v4.5.2Compare Source
v4.5.1Compare Source
v4.5.0Compare Source
github/codeql-action (github/codeql-action)
v4.37.3Compare Source
No user facing changes.
v4.37.2Compare Source
config-fileinput that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, theremote=prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023v4.37.1Compare Source
jdx/mise-action (jdx/mise-action)
v4.2.3: : Restore mise PATH propagationCompare Source
A patch release that restores mise's PATH propagation to subsequent workflow steps — without reintroducing the full-PATH snapshot behavior that v4.2.1 fixed.
Fixed
Export mise PATH entries to subsequent steps (#575) by @jdx
v4.2.1 stopped exporting the complete
PATHreturned bymise env --jsonintoGITHUB_ENV, which correctly prevented snapshotting the runner's environment into subsequent steps. However, that also dropped mise-produced PATH entries — tool shims,[env] _.pathdirectories, and similar — that workflows relied on after the setup step. See #565.The action now computes only the prefix that mise prepended to the existing
PATHand forwards those directories individually throughGITHUB_PATH. This preserves mise's configured ordering, composes cleanly with PATH changes from other actions, and never persists the runner's fullPATHthroughGITHUB_ENV. The dotenv fallback path (used with older mise versions) also stripsPATH=lines and re-derives additions frommise env --json.A new
export_pathinput (defaulttrue) lets workflows keep regularenvexports while opting out of PATH changes:Full Changelog: jdx/mise-action@v4.2.2...v4.2.3
v4.2.2: : Zstd tar fallback for older runnersCompare Source
A small patch release that fixes archive selection on runners with an older
tarand corrects a stale default in the README.Fixed
Verify
tarsupports Zstd before picking.tar.zst(#569 by @JackMyers001The action previously chose the
.tar.zstmise archive wheneverzstd --versionsucceeded, then extracted it withtar --zstd. On RHEL 8-compatible runners that shipzstd1.4.4 alongside GNUtar1.30, the--zstdoption isn't recognized and installation failed.Detection now runs both checks:
If either fails, the action falls back to the
.tar.gzarchive. No configuration change is required — existing workflows on affected runners just start working again. Fixes #568.Documentation
cache_key_prefixexample in the README to reflect the current default ofmise-v1(previously documented asmise-v0) (#570 by @muzimuzhi).New Contributors
Full Changelog: jdx/mise-action@v4.2.1...v4.2.2
v4.2.1: : Signed checksums and PATH export fixCompare Source
A small patch release with two user-facing fixes: mise downloads are now verified against minisign-signed release checksums by default, and the
envinput no longer leaks the runner'sPATHinto subsequent steps.Fixed
Verify mise downloads with signed checksums (#548) by @jdx
The action now embeds mise's minisign public key and verifies
SHASUMS256.txt.minisigbefore trusting any release checksums, then checks the downloaded mise binary's SHA256 against the verified list. This applies to both GitHub release archives (verified before extraction) and the defaultmise.jdx.devCDN path (verified against the signed checksum for the matching release asset). If a CDN download fails verification, the action warns and falls back to the signed GitHub release asset instead of installing an unverified binary.sha256input still works as an explicit override.2024.12.24(which predate minisign checksums) get a warning and skip signed verification rather than failing.download | tarfast path is replaced with a download-then-verify-then-extract flow.Thanks to @potiuk for the detailed threat-model writeup in #547.
Exclude
PATHfrom environment export (#556) by @jdxThe
envinput has always documented that "PATH modifications are not part of this", but since the switch tomise env --jsonin #252 (needed for redaction support), the action was exporting every string value returned by mise — including the computedPATH— intoGITHUB_ENV. That effectively snapshotted the runner's entirePATHinto subsequent steps and let[env] _.pathentries inmise.tomlleak past the action's own PATH management.exportMiseEnvnow skipsPATH(case-insensitive) when exporting JSON env vars, restoring the documented behavior. Normal mise env vars are still exported, and PATH continues to be managed by the action's own setup (e.g.add_shims_to_path). Fixes #555.Full Changelog: jdx/mise-action@v4.2.0...v4.2.1
open-telemetry/shared-workflows (open-telemetry/shared-workflows)
v0.4.0Compare Source
What's Changed
Full Changelog: open-telemetry/shared-workflows@v0.3.1...v0.4.0
v0.3.1Compare Source
What's Changed
Full Changelog: open-telemetry/shared-workflows@v0.3.0...v0.3.1
v0.3.0Compare Source
What's Changed
Full Changelog: open-telemetry/shared-workflows@v0.2.1...v0.3.0
ossf/scorecard-action (ossf/scorecard-action)
v2.4.4Compare Source
What's Changed
This update bumps the Scorecard version to the v5.5.0 release. For a complete list of changes, please refer to the Scorecard v5.4.0 release notes and the Scorecard v5.5.0 release notes.
Full Changelog: ossf/scorecard-action@v2.4.3...v2.4.4
Configuration
📅 Schedule: (UTC)
* 0-7 * * 2)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.